Friday, February 19, 2010

Citizens united (against Citizens United)

Larry Lessig has an interesting posting on the awful Citizens United Supreme Court decision.


He calls for two main actions:
  1. In the short term: passage of the Fair Elections Now Act. See http://www.publicampaign.org/node/38166 for a description of this law that basically calls for citizen-funded elections (donations $100 or less)
  2. In the longer term: a constitutional convention to pass an amendment to the constitution to protect the independence of congress from funders (see http://www.callaconvention.org/pages/call-for-a-convention/ for his reasoning and proposed amendment)
Lessig is a very interesting guy. Years ago I followed a great online class he and a couple of other lawyers ran on Cyberspace Law. I am not a lawyer (mandatory IANAL here :-), but the class was fascinating and accessible...check it out. It is a little old, but he covers the underlying principles, which I imagine can't have changed all that much. Many of the topics covered (copyright law, privacy law, free speech, etc. as they relate to cyberspace are still very hot topics.)

Thursday, February 11, 2010

Eye of the storm

Doesn't this look like something out of Magritte?

We had rather a lot of snow yesterday.

Saturday, February 6, 2010

On the slow track to justice

A week or so ago I was on a train from New York to Princeton. Somewhere before Linden I heard a bit of a hubbub around me and something about "all for $1.75".

It seems that a young man was trying to get a free ride by sneaking on at one station and sneaking off again at the next station, before the conductor came by to collect tickets. Unfortunately for him, the conductor came by a little too soon. And still more unfortunately for him, it seems that this wasn't the first time he was caught in this behavior. It was his third strike.

The conductor, only slightly older than the culprit, gleefully radioed for reinforcements. So along came the older head conductor, as well as a third conductor to join in the sport. They needled him for a while, and finally, not knowing how else to extract any satisfaction from him, radioed for the police to pick him up at Linden.

The train pulled in to Linden. And waited for the police to arrive. For about 20 minutes. And then waited for the police to debrief the conductors for about 10 minutes. During which time no one was allowed on or off the train, including passengers who just wanted to get off at Linden. Luckily I was in no particular rush, but there were a number of fairly antsy people around.

During all this waiting, I had some leisure to reflect on the incident.

The predominating question in my mind was: who stood to benefit from this exercise in justice? Why was so much collective time allowed to be spent on addressing such a petty "crime"?

Consider how much time was involved: at least one trainful of people, containing possibly hundreds of passengers, was delayed for half an hour, and who knows how many other trains with how many other passengers were held up behind ours? In addition, no fewer than three police officers appeared on the scene to interrogate the dangerous fare-jumper, diverted from protecting the citizens of Linden from other dangers. Who knows what the delays may have cost the passengers, in terms of lost opportunities, irritation to their customers or colleagues or families? Had I been on my way to, say, a job interview, I would undoubtedly have been frantic at the delay. To be fair, I think that the conductors, had they known that the process would be so slow, would have contented themselves with throwing the guy off the train at Linden with a couple of savory curses.

What was the value in spending all this time to punish a $1.75 crime? At the time, it felt like the purpose of the exercise, in the minds of the conductors, was to demonstrate to the world that they were there to uphold the social contract. It wouldn't be fair, after all, to the law-abiding, paying passengers to let some thief off scot-free. And besides, they weren't going to let some dumb-ass criminal make a monkey of them. Probably there were a few people on the train who felt the same way. But I think the majority of the law-abiding, paying passengers on that train would have cheerfully allowed the social contract to be broken in this instance, if only to get to where they were going on time. Clearly there's more at stake than $1.75, but it's not clear to me how much. Is fare-jumping a major revenue-loss for the the trains? I don't know. But it would have to be a pretty significant one, to make a delay like that worthwhile. No one from NJ Transit bothered to share that information with us.

It's a common theme in security: you don't spend more on protecting something than that thing is worth.

Monday, January 25, 2010

Some words of inspiration

I'm sorry, I'm sorry, I'm sorry. (No, those aren't the words). I can't believe it's been over 2 weeks already! Today I put a recurring bi-weekly reminder on my calendar at work to remind me to be sure and put a post up at least every two weeks. It won't happen again!

Anyway...


A couple of days ago, I got the best fortune cookie. It reads:

Engage in group activities that further transformation.

It's so...fortune cookie.

And yet, isn't that something we'd all like to do? Work with other people to change the world?

I wonder if this one goes with the other fortune cookie I got recently:

Solid gains are possible today. With a headache.

I hung that one outside of my cube. So far, no one around me has complained of a headache.

Sunday, January 10, 2010

Can't get something for nothing

So the latest dangerous-product-from-China scandal is kiddie jewelry.

Seems that in an effort to cut prices while following US regulations, the jewelry producers have cooperatively removed the lead, but substituted it with cadmium, another nasty heavy metal, carcinogen, brain-stunting, all that. It seems that there's no rules against cadmium in kid's jewelry.

Oops.

When will we, as a nation, realize that there is a hidden cost in cheap stuff?

Cheap products are made of cheap stuff. And sometimes that stuff is cheap because it's less desirable (for example, less healthy). Think melamine. Think heparin. If something looks too cheap to be true, it is. The company is going to cut corners to make a profit.

Is buying more cheap stuff for our kids really worth it, at the expense of their health? At the expense of the jewelry workers' health? At the expense of the jewelry workers' living wage?

Friday, January 8, 2010

Out with the old, In with the new!

Well...it's been a while, but I think that's going to change. About a month ago, I made a deal with Sharney that starting with the new year I would update my blog at least once every two weeks, if she would do the same. So Sharney, we're on! Let's go, girl! Here's to the expression of new thoughts and insights for the new year!

From most points of view, I can't say goodbye to 2009 (and for that matter the aughts or the naughts or whatever you'd like to call that abysmal decade) fast enough. (Annapurna pretended to be offended by my lack of respect for the decade, and then she pretended to be mollified when I told her that there were some silver linings.) But really, from the "surge" in Afghanistan to the huge giveaway to the health insurance industry we're on the brink of, let's just say I'm less than enthusiastic about our prospects for the future. But hope springs eternal, and maybe better things will turn up in 2010.

I was going to bore you with a trivial review of many of the books I read last year (and I may yet become sadistic or desperate enough to go through with that plan), but instead, I think I'll open the year with a very apt cartoon I just saw, courtesy of Bruce Schneier.

As a once-upon-a-time student of pattern recognition/machine learning/data mining techniques, this cartoon appeals to me -- real data often looks rather like this. As a security nut, I can assure you, this is a serious issue in (IT) security. There is a rather large industry devoted to developing tools and techniques for distinguishing between real intrusions and false alarms, and still the majority of alarms do turn out to be false.


This country has a tendency to want to assign blame to someone whenever anything goes wrong. Sometimes that's useful, and sometimes we do learn to fix mistakes. Just to be clear, in the case of the underwear bomber, I think the pattern looked more like

But, in general, I think there's too much of a tendency to demand action, where there is really no good basis for action. The net result is that as a society, we look for patterns and find those we wish to see rather than spending our efforts on activities that may actually help us make things better.

Sunday, July 19, 2009

Some recent visitors

This summer I opened a 24-hour cafeteria on my kitchen window. It's quite popular in the neighborhood. There's sometimes even a queue on the railing outside.
I believe this fellow is a House Finch. We also get a lot of sparrows, blue jays and Tufted Titmice, but I don't have photos of these.
We also have an acrobatic squirrel. He jumps from the railing or the screen to the feeder, and sometimes even manages to get in. He's been caught in there, though I don't have a photo to prove it. (Annapurna managed to get a video!) I think maybe he's licking his wounded pride here, at another miss.

Wednesday, March 11, 2009

Word/Phrase History -- Pimping

I found a use of the word "pimping" in Shamela (published 1741):

In the Character of Mrs. Jewkes Vice is rewarded; whence every Housekeeper may learn the Usefulness of pimping and bawding for her Master.
Did they do stuff like that in 1741? :-)

Pimp doesn't seem to be listed on Word Detective, so I can't compare notes that way.

Saturday, February 28, 2009

Word/Phrase History -- Bamboozle

Every so often I see a word or phrase in a fairly old text (say 2 or 3 hundred years old), and I think "That's odd...I would have thought that was a modern sort of word!" I've been planning for some time to keep a list of such words, and this is as good a place as any to put it.

So today's word is "bamboozle". Now, had I thought about it (which I admit I hadn't), I would have guessed that bamboozle was a '70's sort of word. Or maybe Roaring 20's. However, I ran across it last year while reading Cecilia (published in 1782), and more recently while recording a chapter of it for Librivox. In Volume Two, Chapter III, wealthy Cecilia's batty, miserly guardian, dressed up as a chimney sweep at a costume party is worried about her trying to run off with a gold digger:

" 'Ah ha!' cried the chimney-sweeper, significantly nodding his head,'smell a rat! a sweetheart in disguise. No bamboozling! it won't do; a'n't so soon put upon.' "
My Random House College Dictionary has this definition of bamboozle: "1. to deceive or get the better of (someone) by trickery, flattery or the like; humbug; hoodwink. 2. to perplex or mystify." It offers no etymology for the word. In such situations, I generally turn to one of my favorite references, namely The Word Detective by Evan Morris. He's got an excellent list of words and their etymologies, histories, etc. each described quite wittily. He finds that bamboozle was used as early as 1710 by Jonathan Swift, though the origins of the word are in dispute.

Friday, December 12, 2008

Electronic Medical Records -- at what cost?

President-elect Barack Obama has made Electronic Medical Records (EMRs) one of the centerpieces of his plans for economic stimulus and healthcare reform. Now I'm certainly in favor of both stimulus and greater access to healthcare with lower costs, but I have some serious concerns about the use of EMRs to accomplish this. While automation would undoubtedly improve the productivity of healthcare delivery, it is also likely to improve the productivity of misuse. And considering how sensitive health information is, we need to be extra careful about building in safeguards against misuse. I just don't have a lot of faith that those safeguards will be thought out or implemented properly.

Let me start with the good part. The expectation, as I understand it, is that EMRs would
  1. provide stimulus by employing a large number of IT and healthcare professionals to implement the EMR infrastructure

  2. improve healthcare quality by centralizing information about a patient, to enable more informed decisions by healthcare providers (thereby also reducing dangerous errors)

  3. reduce healthcare costs by reducing duplication of services, dangerous errors and insurance fraud

  4. though nobody mentions it much, these days, I'd have to say another benefit would be the research that would be enabled: with large bodies of patient information, it would become possible to analyze more thoroughly the efficacy and safety of various drugs and treatment protocols, as well as disease models, etc.

Now I'm all for these goals. Especially the bit about employing more IT professionals. Not to mention the bit about helping scientific research (I still have a soft corner for AI and medicine, and all that, don't you know?) And I do believe that all of these benefits would ultimately be realized.

However, there are two main classes of concerns that I have:

  1. I don't see net cost savings any time soon (like any time in the next 8 years)

  2. I see massive societal risks to consolidating patient information
We're already up to our ears in debt, and we need some big spending to get our economy going, so what the heck? Cost savings isn't the gamechanger in my mind. I consider the societal risks the more serious issue, so let's begin with that.

First of all, I hereby admit that I haven't been able to find any details on exactly what an Obama administration would call for, in terms of EMRs. And the exact risks depend on the exact model. From a purely productivity point of view, I imagine that the ideal thing would be for a massive central database of health records for every patient in the country. It is possible that Obama envisions something rather different, such as a sort of federation of independently owned and operated databases managed by different stakeholders, with rules about when and how they can exchange data. But even in a de-centralized approach, there would almost certainly be design requirements to ensure ease of exchange of information, which in practice would probably lead to more or less aggregation of information about individuals. So most of my comments will address the risks of a centralized database. However, you may be certain that arguments over the exact model (centralized or federated or ...) will dominate the first several years of the effort -- different parties (companies, industries, trade and professional organizations, etc.) will have a lot at stake in the decision of what model to adopt. Hence some of my cynicism about when we can expect to see any savings. But I digress.

So what sort of risks are we looking at? I can't begin to do justice, but here's some broad categories:

  1. Risks from malicious outsiders (hackers, etc.)
    A massive database of patient information would be an exceptionally juicy target for all sorts of hackers for all sorts of reasons. It would be a fantastic target for a Denial of Service attack: just imagine the havoc you could wreak by taking the system down -- the health of millions of people could be put in jeopardy. (Denial of Service would be less of an issue in a de-centralized model.) It would also be a terrific target for all sorts of hackers aiming for shake-down information about specific individuals (e.g. politicians, celebrities, annoying next door neighbors, ex-girlfriends, etc.)

  2. Risks from (malicious) insiders (people who have legitimate access to data but misuse it)
    Anyone remember the flap last spring about those naughty State Department contractors who peeked at Obama's passport records? Just imagine that on steroids. Again, we're talking about all kinds of possibilities of improper access to peek at records of politicians, celebrities, annoying next door neighbors, ex-girlfriends, etc. Some of this can be prevented with proper auditing (which was responsible for catching the passport peekers). But given the large number of people potentially involved in providing healthcare services, I believe that there is still considerable risk from this. Of course, there could be some entertainment value. Imagine the fun that we'd have when unnamed sources from a large hospital divulged to the National Enquirer that some pro-life candidate once had an abortion 10 years ago :-) Oh yeah, and apart from the malicious thing, how long until some contractor goes out for lunch carrying around health records for 300,000 patients and loses the laptop?

  3. Risks based on poorly designed policy (who do we give access to the data and what are they allowed to do with it?)
    Number one on my list would have to be: what do insurance companies get access to and what do they get to do with it? Full patient information for health care providers also potentially means full information for insurance companies to simplify their cherry picking. We need to build in anti-discrimination policy. This would be far less of a worry to me if we were looking at a single payer system -- ain't gonna happen. Number two on my list would probably be the financial pressure for targeted direct-to-consumer marketing. What a gold mine for pharmaceutical companies (and/or hospitals co-marketing on their behalf)!

  4. Risks based on poorly designed processes
    I recently read a piece by Tom Yager which really gives me pause. He describes a rather unpleasant personal experience with e-prescription (a small part of EMRs), which almost amounted to a denial of service for him. When you're talking about things that people's lives depend on on a day-to-day basis, you've got to be especially careful to not hold them up because "the system said so". But it's not easy (and it is fraud-prone) to build flexibility into a system. Also, consider the potential for errors and identity confusion. Imagine your situation if somebody entered a positive HIV test result in your record, intending it for someone else with the same name? There's been lots of fun with the no-fly list (google David Nelson no fly). Imagine the fun with a nation-sized list (a couple of orders of magnitude larger). By the way, this is one place where a single centralized database might work a little better, in that you could have a national ID that could uniquely identify you. Oh, I forgot...Social Security Numbers...identity theft. Forget I mentioned that.
Apart from the risks inherent in EMRs, I see the cost-savings as gradual, at best. If we're talking about a single central database, you can just forget about it until oh, I don't know, maybe some time before Sasha and Malia O. retire. A typical largish project, in my experience requires about
  • A year to argue about what the project goals are (scope, standards, etc.)
  • A year to decide on an approach to the project (technologies, buy-vs-build, players, etc.)
  • About two years to implement a rudimentary system that achieves about 60% of What We Really Want -- enough to give an illusion of business as usual, but not enough to feel really comfortable
  • A year or so to get people up and running with the rudimentary system and develop workarounds for the kinks in the system
  • Several more years to evolve to a mature system with most of the functionalities that users need and just a few annoyances
And mind you, I've never worked on a really large, government-sized, industrial strength project. (I have worked on a smallish government project, and it's in the mature stage where non-radical changes take 8 months.) If we're not talking about a single central database, change could be achieved more quickly, but delay will arise due to incompatibilities between independently developed systems that will need to interoperate. And don't forget, once there are systems in place, it will take time to get data from existing paper records into electronic format. Again, I think we can expect that once a system's in place, there will be savings. Just don't expect a quick payoff.

So am I saying we shouldn't implement Electronic Medical Records? No, I don't think so. No more than I am saying that we should ban pencils because some people use them to write hate literature. No more so than that we should forget about computers because they cost more and are more complicated than pencils and paper.

But I would call for some sober reflection on what we are getting into.


Edited 1/12/09: CNN has an interesting piece which makes many of the same points. It has some useful statistics, I think.

http://money.cnn.com/2009/01/12/technology/stimulus_health_care/index.htm